1amends "../../config/Service.pkl"
2
3import "../../config/site.pkl" as site
4
5meta { name = "Tailscale" }
6
7container {
8 image = "docker.io/tailscale/tailscale@sha256:2667499ed87ae29218f292556ba062918402dd5e92e93637af14867e4df12dd3"
9 // The node joins the tailnet through its own network stack and TUN device.
10 hostNetwork = true
11 imageUser = true
12 cpu = 100
13 memory = 256
14 capAdd { "NET_ADMIN"; "NET_RAW" }
15 devices { "/dev/net/tun" }
16
17 volumes {
18 ["/var/lib/tailscale"] {}
19 }
20
21 env {
22 ["TS_HOSTNAME"] = site.nodeName
23 ["TS_STATE_DIR"] = "/var/lib/tailscale"
24 ["TS_USERSPACE"] = "false"
25 ["TS_AUTH_ONCE"] = "true"
26 ["TS_ACCEPT_DNS"] = "false"
27 ["TS_BOOT_TIMEOUT"] = "1h"
28 }
29}